Entra IDHow-to

Privileged Identity Management: just-in-time Microsoft Entra roles done properly

Set up PIM for Microsoft Entra roles: role settings, eligible assignments, activation and approvals, PIM for Groups, alerts, access reviews, and the activation problems you'll hit.

Standing Global Administrators are the easiest win for an attacker and the hardest thing to explain to an auditor. Privileged Identity Management (PIM) turns permanent role assignments into eligible ones that admins activate for a few hours, with MFA, a justification and optionally an approval. In this post I'll walk through the concepts, the role settings that matter, the activation and approval flow, PIM for Groups, alerts and reviews, and the activation problems that generate most of the tickets.

How this guide is organised: Prerequisites → How it works → Step-by-step → PIM for Groups → Alerts and access reviews → Verify → Tips & gotchasFlow diagram of the article's sections in reading order: 1. Prerequisites. 2. How it works. 3. Step-by-step (3 steps: Configure role settings; Convert standing admins to eligible; Activate, approve, deactivate). 4. PIM for Groups. 5. Alerts and access reviews. 6. Verify. 7. Tips & gotchas. Toolbox: Role settings › Edit, Alerts › Setting, MS-PIM, Access reviews › New.1Prerequisites2How it works3Step-by-step4PIM for Groups1Configure role settings2Convert standing adminsto eligible3Activate, approve,deactivate5Alerts and accessreviews6Verify7Tips & gotchasTOOLBOXRole settings › EditAlerts › SettingMS-PIMAccess reviews › NewHow this guide is organised: Prerequisites → How it works → Step-by-step → PIM for Groups → Alerts and access reviews → Verify → Tips & gotchasFlow diagram of the article's sections in reading order: 1. Prerequisites. 2. How it works. 3. Step-by-step (3 steps: Configure role settings; Convert standing admins to eligible; Activate, approve, deactivate). 4. PIM for Groups. 5. Alerts and access reviews. 6. Verify. 7. Tips & gotchas. Toolbox: Role settings › Edit, Alerts › Setting, MS-PIM, Access reviews › New.1Prerequisites2How it works3Step-by-step1Configure role settings2Convert standing admins to eligible3Activate, approve, deactivate4PIM for Groups5Alerts and access reviews6Verify7Tips & gotchasTOOLBOXRole settings › EditAlerts › SettingMS-PIMAccess reviews › New
At a glance: how this guide is organised · 3 steps · 4 key settings and tools

Prerequisites#

  • Licensing: Microsoft Entra ID P2 or Microsoft Entra ID Governance (also part of Microsoft Entra Suite). You need a licence for every user with an eligible or time-bound assignment, every approver, and everyone reviewing or being reviewed in a role access review. If the licence lapses, eligible assignments are removed.
  • Roles: Privileged Role Administrator (or Global Administrator) manages assignments and role settings; Security Administrator, Security Reader and Global Reader can view them.
  • Emergency access: two cloud-only accounts permanently assigned Global Administrator, excluded from Conditional Access and never made eligible.
  • Nothing to switch on: once the tenant is licensed PIM is available immediately; the MS-PIM service principal appearing in audit logs is expected.

How it works#

TermMeaning
EligibleThe user must activate before using the role. Once active, the permissions equal a permanent assignment.
ActiveUsable straight away. Both eligible and active assignments can be permanent or time-bound.
ActivationThe steps the role settings demand (MFA or an authentication context, a reason, a ticket number, approval), producing a temporary active assignment capped by the maximum duration.
Extend / renewUser-requested before or after a time-bound assignment expires; a Privileged Role Administrator or Global Administrator approves.

Step 1: Configure role settings#

Settings are per role, and every assignment of that role follows them. Go to ID Governance › Privileged Identity Management › Microsoft Entra roles › Roles, select the role, then Role settings › Edit.

SettingWhat I recommend
Activation maximum duration1 to 24 hours. Four hours suits most roles; shorter for Global Administrator.
On activation, requireEither Microsoft Entra ID multifactor authentication or Microsoft Entra Conditional Access authentication context. Use the context for phishing-resistant MFA, a compliant device or terms of use at activation time.
Require justification / ticket informationJustification yes. The ticket field is free text; nothing validates it.
Require approval to activateYes for Global Administrator, Privileged Role Administrator and similar. Pick at least two approvers; with none selected, active Privileged Role Administrators and Global Administrators approve by default.
Assignment durationAllow permanent eligible assignments or make eligibility expire; the same choice exists for active assignments, plus MFA and justification when an active assignment is created.
NotificationsPer email type, change recipients or keep critical emails only.

Watch out: you lock yourself out if every Global Administrator and Privileged Role Administrator is only eligible, approval is required, and no approvers are configured. Keep the emergency access accounts permanently active and name specific approvers.

Authentication context done right#

Create and enable the Conditional Access policy that targets the authentication context before you reference it in the role settings. Scope it to all users or the eligible users, never to the directory role: during activation the user doesn't hold the role yet, so a role-scoped policy wouldn't apply. For a prompt on every activation, add the sign-in frequency session control set to Every time; a 10-minute window then covers further activations across Entra roles, Azure roles and PIM for Groups. If no policy targets the context, PIM falls back to requiring MFA, but that safety net doesn't trigger when the policy is disabled, in report-only mode or excludes the user. A second policy scoped to the directory role protects what the admin does after activation.

Step 2: Convert standing admins to eligible#

Open Microsoft Entra roles › Discovery and insights (preview). Reduce Global Administrators and Eliminate standing access list the permanent assignments and let you select users and choose Make eligible or Remove assignment. For new people, use Roles, select the role, then Add assignments and choose an eligible assignment with a duration the role settings allow.

Step 3: Activate, approve, deactivate#

  1. The admin goes to ID Governance › Privileged Identity Management › My roles › Microsoft Entra roles and selects Activate next to the role.
  2. If prompted, they complete Additional verification required. This happens once per session.
  3. They can reduce the scope, set a custom start time, enter the reason and select Activate. If approval is required, a notification says the request is pending and it appears under My requests, where it can also be cancelled.
  4. Approvers get an email and act in Approve requests, entering a justification. The first approver to respond decides, approvers can't approve their own requests, and a request not approved within 24 hours expires. That window isn't configurable.
  5. Once active, a Deactivate button appears, but not within the first five minutes of activation.

Scripted activation uses the same Microsoft Graph API the portal does:

Text
POST https://graph.microsoft.com/v1.0/roleManagement/directory/roleAssignmentScheduleRequests
{
  "action": "selfActivate",
  "principalId": "<user object id>",
  "roleDefinitionId": "<role template id>",
  "directoryScopeId": "/",
  "justification": "Change CHG0012345: mailbox migration",
  "scheduleInfo": { "expiration": { "type": "AfterDuration", "duration": "PT4H" } }
}

PIM for Groups#

PIM for Groups makes membership or ownership of a security or Microsoft 365 group eligible, with separate member and owner policies. Dynamic groups and on-premises synced groups can't be enabled. A group doesn't have to be role-assignable to be managed by PIM, but one assigned a Microsoft Entra role must be, and a tenant can have at most 500 role-assignable groups. Groups that grant roles should require approval; otherwise an admin who can reset a member's credentials could activate on their behalf.

Note: to give just-in-time access to Exchange, SharePoint or Purview roles, make the users active members and make the group eligible for the role, or use PIM for Entra roles directly. Making users eligible for a group that holds the role is documented to cause activation delays, and SharePoint and OneDrive can return "Access denied" for up to 24 hours.

Alerts and access reviews#

Under Microsoft Entra roles › Alerts › Setting, tune the built-in alerts: Roles are being assigned outside of Privileged Identity Management (high), Potential stale accounts in a privileged role (medium), and low-severity ones such as There are too many Global Administrators and Roles are being activated too frequently. Then create a recurring review under Microsoft Entra roles › Access reviews › New: choose eligible, active or all assignments, selected reviewers or self-review, enable Show recommendations (based on 30 days of sign-ins) and decide what happens if reviewers don't respond. Selecting several roles creates one review per role.

Verify#

  • My roles › Active assignments shows the role with its end time, and the admin can perform the privileged task.
  • Microsoft Entra roles › Resource audit lists the activation, the approver's decision and the deactivation.
  • In the Entra sign-in logs, the activation sign-in shows the authentication context policy under the Conditional Access tab.
  • The weekly PIM digest and alert emails arrive for the recipients you configured.

Tips & gotchas#

  • "It never asked me for MFA." Documented behaviour: a user who already satisfied MFA in the session, including through a Windows Hello for Business sign-in, isn't prompted again. Use the authentication context with sign-in frequency Every time for a fresh prompt.
  • Activation blocked by Conditional Access. Check the policy targeting the authentication context: enabled (not report-only), user in scope, device compliant, authentication strength registered. The user sees a message that a Conditional Access policy may require additional verification and must select it to continue.
  • Role active, access still denied. PIM creates the assignment within seconds, but applications cache role state. Signing out and back in usually helps; the SharePoint and OneDrive case above is the documented exception.
  • Approval expired. After 24 hours the requester must submit a new request, so use a group as approver rather than one person.
  • Teams on mobile asks the user to reopen the app after an activation to keep receiving notifications. By design.

References#

Written and checked against current Microsoft Learn documentation. Test changes with a pilot group before rolling them out to everyone, and if an admin center path has moved since, search for the setting name instead.

Spotted a mistake, or did this fix work differently for you? Email me or message me on LinkedIn — corrections are credited in the article.

OE
Written by

Omer Eltayeb

Independent Microsoft Intune consultant in Cairo, Egypt, former Microsoft Cloud Solutions Architect, Microsoft Certified Trainer and Microsoft Innovative Educator Expert (2024–26) and Microsoft Elevate Educator Expert (2026–27). I share practical, step-by-step guides, study plans, scripts and toolkits for Microsoft Intune, Microsoft Entra ID, Microsoft Defender and Exchange Online with the community.

Microsoft Certified Trainer (MCT) 2026Microsoft Innovative Educator Expert 2025–2026Microsoft Elevate Educator Expert 2026–2027ISC2 Certified Information Systems Security Professional (CISSP)Microsoft 365 Certified: Enterprise Administrator Expert (MS-102)